Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Penetration Testing

Penetration testing methodologies, frameworks, reporting, and automation tools.

NewestRelevanceMost popularRecently updated
19033 results
CVE-2023-48795 preview

CVE-2023-48795

GitHubhav0cx0/cve-2023-48795

Scans SSH servers for Terrapin-affected OpenSSH versions by grabbing banners over port 22, enabling quick internal audits, penetration testing, and…

vulnerability-scannersvulnerability-analysisinformation-gathering+2
1 year ago
cve-2025-5781_FreePBX preview

cve-2025-5781_FreePBX

GitHubiamrajkumar1995/cve-2025-5781_freepbx

Proof-of-concept exploit for FreePBX Endpoint module CVE-2025-5781: chains unauthenticated SQL injection with database manipulation and scheduled…

vulnerability-analysisexploitationweb-application-exploitation+1
5 days ago
CVE-2026-42945_NginxRift preview

CVE-2026-42945_NginxRift

GitHubkentox493/cve-2026-42945_nginxrift

Automates CVE-2026-42945 exploitation in NGINX containers: verifies vulnerable targets, brute-forces heap offsets, executes commands, and opens an…

container-securityvulnerability-analysisexploitation+5
6 days ago
POC-GeoLeak-CVE-2026-52715 preview

POC-GeoLeak-CVE-2026-52715

GitHub686f6c61/poc-geoleak-cve-2026-52715

PoC funcional de CVE-2026-52715 (GeoLeak): SQLi no autenticada en GEO my WordPress <= 4.5.5 via swlatlng/nelatlng. Laboratorio Docker + exploit…

vulnerability-analysisexploitationweb-application-exploitation+4
6 days ago
CVE-2024-6333 preview

CVE-2024-6333

GitHub0xqrx/cve-2024-6333

Authenticated Remote Code Execution vulnerability in Xerox WorkCentre printers via the Network Troubleshooting Log feature.

embedded-systems-securityexploitationweb-application-exploitation+2
6 months ago
CVE-2023-22047---Oracle-PeopleSoft-LFI preview

CVE-2023-22047---Oracle-PeopleSoft-LFI

GitHub0xterror/cve-2023-22047---oracle-peoplesoft-lfi

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

vulnerability-analysisexploitationweb-application-exploitation+3
5 days ago
CVE-2026-72898 preview

CVE-2026-72898

GitHub4minx/cve-2026-72898

Proof-of-concept exploit for CVE-2026-72898, an unauthenticated SQL injection in Metabase's password-reset endpoint. Forges an admin session for full…

vulnerability-scannersvulnerability-analysisexploitation+3
16 days ago
CVE-2023-22047-Oracle-PeopleSoft-LFI preview

CVE-2023-22047-Oracle-PeopleSoft-LFI

GitHub0xterror/cve-2023-22047-oracle-peoplesoft-lfi

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

vulnerability-analysisexploitationweb-application-exploitation+3
5 days ago
CVE-2026-46300_Fragnesia preview

CVE-2026-46300_Fragnesia

GitHubkentox493/cve-2026-46300_fragnesia

Linux kernel local privilege escalation exploit with automated prerequisite audit for CVE-2026-46300, validating patch status, XFRM ESP-in-TCP…

privilege-escalationvulnerability-analysisexploitation+3
6 days ago
CVE-2026-53587 preview

CVE-2026-53587

GitHubalixploit22/cve-2026-53587

Python proof-of-concept for CVE-2026-53587, providing a focused exploit path to reproduce the vulnerability and support validation and defensive…

vulnerability-analysisexploitationpenetration-testing
5 days ago
CVE-2026-6440 preview

CVE-2026-6440

GitHubalixploit22/cve-2026-6440

mencari sebuah kerentanan, wodpres dan mengungah shell di kerentanan wodpres tersebut

vulnerability-analysisexploitationweb-application-exploitation+2
5 days ago
CVEX2SHEL preview

CVEX2SHEL

GitHubalixploit22/cvex2shel

Exploit for CVE-2026-64638, a pre-authentication reflected XSS in WordPress login, enabling injection of malicious JavaScript into /wp-login.php…

vulnerability-analysisexploitationweb-application-exploitation+2
5 days ago
CVE-2026-8794 preview

CVE-2026-8794

GitHubh4zaz/cve-2026-8794

Username Enumeration via Authentication Timing Side-Channel in PaperCut NG

reconnaissancevulnerability-analysisweb-application-exploitation+4
6 days ago
bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork preview

bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork

GitHubhunt-benito/bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork

PoC exploit for CVE-2026-73678: unauthenticated RCE in MindsDB Cowork via attacker-supplied LLM key and unsandboxed scratchpad exec to run OS…

vulnerability-analysisexploitationweb-application-exploitation+4
6 days ago
CVE-2026-9090-poc preview

CVE-2026-9090-poc

GitHubkimdir01/cve-2026-9090-poc

PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.

payload-generationvulnerability-analysisexploitation+4
5 days ago
CVE-2026-42533 preview

CVE-2026-42533

GitHubleeyoonjoo/cve-2026-42533

CVE-specific proof-of-concept written in Python for vulnerability validation and security testing.

vulnerability-analysisexploitationpenetration-testing
7 days ago
CVE-2025-32433-PoC-Analysis preview

CVE-2025-32433-PoC-Analysis

GitHubliam-worsley/cve-2025-32433-poc-analysis

This is an analysis for CVE-2025-32433 (Erlang OTP SSH Vulnerability). I did not write any of the code, I only wrote comments describing what the…

authentication-authorizationvulnerability-analysisexploitation+4
6 days ago
Perform-an-RDP-exploitation-using-the-BlueKeep-vulnerability-CVE-2019-0708-on-Windows preview

Perform-an-RDP-exploitation-using-the-BlueKeep-vulnerability-CVE-2019-0708-on-Windows

GitHubmohaimenul370/perform-an-rdp-exploitation-using-the-bluekeep-vulnerability-cve-2019-0708-on-windows

Step-by-step demonstration of BlueKeep CVE-2019-0708 exploitation against Windows Remote Desktop Services, including RCE via crafted RDP packets and…

vulnerability-analysisexploitationnetwork-security+2
7 days ago
Previous1…567…1058Next